here is the form $s is the session ID
Expand|Select|Wrap|Line Numbers
- <?php echo"
- <form action = \"chpw.php?d='$s'\" method = 'POST'>
- NEW PASSWORD: <input type='text' name='pass'>
- <br/>
- <input type='submit' value='Submit Password'><br/>
- </form>"; ?>
here is the script that updates
Expand|Select|Wrap|Line Numbers
- <?php
- //$password = md5($_POST['pass']);
- //$s=$_GET['d'];
- //$s=$_POST['id'];
- if(md5($_POST['pass'])== ''){
- echo ('invalid password');
- }else
- $sql="UPDATE account SET Password='".md5($_POST['pass'])."' WHERE StudId='".$_GET['d']."'";
- $result=mysql_query($sql);
- if (!$result)
- die('Error: ' . mysql_error());
- echo "Password Changed Successfully!<br><br>\n";
- header('location: pwlogout.php');
- exit();
- ?>